HashiCorpCVE-2026-14869
HashiCorp Tooling: server-side request forgery
High8.6CVE-2026-14869 · Published Jul 28, 2026 · updated Jul 30, 2026
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Tooling Product | >= 0.3.0, < 1.1.0 | 1.1.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More HashiCorp advisories
All HashiCorp| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | HashiCorp Consul: denial of service | Medium5.3 | 2.0.3+1 more |
| Aug 7 | Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are... | Medium4.2 | 2.0.3+1 more |
| Jul 29 | HashiCorp Tooling: server-side request forgery | High8.6 | 0.1.4 |
| Jul 29 | In consul-mcp-server | Critical10.0 | 0.1.4 |
| Jul 28 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant... | Critical10.0 | 1.1.0 |
| Jul 28 | HashiCorp Tooling: session fixation | High8.9 | 1.1.0 |